Description
HCL BigFix Quantum Risk Analyzer binary lacks several critical, industry-standard hardening protections that could allow an attacker to cause a stack-based buffer overflow.
Published: 2026-08-26
Score: 3.9 Low
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Analysis and contextual insights are available on OpenCVE Cloud.

Remediation

No vendor fix or workaround currently provided.

Additional remediation guidance may be available on OpenCVE Cloud.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 28 Aug 2026 21:00:00 +0000

Type Values Removed Values Added
First Time appeared Hclsoftware
Hclsoftware bigfix Quantum Risk Analyzer
Vendors & Products Hclsoftware
Hclsoftware bigfix Quantum Risk Analyzer

Thu, 27 Aug 2026 17:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 26 Aug 2026 23:15:00 +0000

Type Values Removed Values Added
Description HCL BigFix Quantum Risk Analyzer binary lacks several critical, industry-standard hardening protections that could allow an attacker to cause a stack-based buffer overflow.
Title HCL BigFix Quantum Risk Analyzer is affected by a stack-based buffer overflow
Weaknesses CWE-121
References
Metrics cvssV3_1

{'score': 3.9, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:L/I:L/A:L'}


Subscriptions

Hclsoftware Bigfix Quantum Risk Analyzer
cve-icon MITRE

Status: PUBLISHED

Assigner: HCL

Published:

Updated: 2026-08-27T16:05:13.677Z

Reserved: 2026-01-05T16:08:06.682Z

Link: CVE-2026-21807

cve-icon Vulnrichment

Updated: 2026-08-27T16:04:55.319Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-08-26T23:17:12.713

Modified: 2026-08-28T16:06:43.297

Link: CVE-2026-21807

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-28T20:32:23Z

Weaknesses